Privacy Policy
KitForge · Last updated: August 3, 2026 · ← Back to kitforge.app
What we collect
- Account data: name, email address, password (bcrypt-hashed, never stored in plain text).
- Brand data: briefs, brand names, descriptions and preferences you enter to generate kits.
- Usage data: generation history, job logs, hosted-page view counts, audit log of account actions.
- Payment data: processed entirely by Paddle.com — we never see or store your card details.
How we use it
- Provide the service: generate and store your brand assets, operate your account.
- Transactional email: receipts, password resets, delivery notifications (no marketing without opt-in).
- Security and abuse prevention; service improvement via aggregated, non-identifying statistics.
Third-party processors
- Paddle.com — payments (Merchant of Record).
- AI providers (Recraft, Ideogram, Featherless) — receive your brief text to generate assets. No account credentials are shared with them.
- Cloudflare — DNS, CDN and edge security.
Data retention & deletion
Your assets are stored until you delete your brand or account. Deleting your account removes personal data within 30 days, except records we must keep for legal/accounting reasons (anonymized where possible). You can export your full kit (ZIP) at any time before deletion.
Cookies
We use only essential cookies/local storage for authentication sessions. No advertising or cross-site tracking cookies.
Security
Passwords are bcrypt-hashed; sessions are token-based with rotation; tenant data is isolated at the database level (row-level security); traffic is encrypted in transit via TLS.
Your rights
Email [email protected] to access, correct, export or delete your personal data. EU/UK users: you have GDPR rights including access, rectification, erasure, portability and objection.
Contact
KitForge · [email protected] · kitforge.app